> For the complete documentation index, see [llms.txt](https://developers-apps-in-toss.toss.im/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developers-apps-in-toss.toss.im/api/en/user-key.md).

# User identification key

## Validate anonymous user identification key

> It verifies whether the anonymous user identification key passed in the x-anon-key header is valid.\
> \
> \### Business error code\
> \
> The errors below return with HTTP 200 and \`resultType: FAIL\` response.\
> \
> \| errorCode | Description                                     |\
> \| --------- | ----------------------------------------------- |\
> \| \`4010\`    | Authentication information could not be found.  |\
> \| \`4095\`    | Request limit exceeded. Please try again later. |\
> \
> \*\*Request limit\*\*: 3,000 times per minute per app

```json
{"openapi":"3.1.0","info":{"title":"Apps in Toss Partner API","version":"1.0.0"},"tags":[{"description":"This is the API used when validating user identification keys in partner apps.","name":"user-key"}],"servers":[{"description":"Operations (for simple login, message sending, Toss Points payout, etc.)","url":"https://apps-in-toss-api.toss.im"}],"security":[{"mutualTLS":[]}],"components":{"securitySchemes":{"mutualTLS":{"description":"This is mTLS authentication based on a client certificate issued to the partner. The mini app is identified by the certificate's CN. For how to issue and manage certificates, [Using the server API](https://developers-apps-in-toss.toss.im/documentation/integration/server-api) please refer to the documentation.","type":"mutualTLS"}},"schemas":{"TossApiSuccessBoolean":{"description":"This is the success response envelope.","properties":{"resultType":{"description":"This is the processing result. On success, `SUCCESS` it is.","enum":["SUCCESS"],"type":"string"},"success":{"description":"This is the actual response data on success.","type":"boolean"}},"required":["resultType","success"],"type":"object"},"TossApiFail":{"description":"This is the failure response envelope. Business errors are returned with HTTP 200, so `resultType` be sure to check it.","properties":{"error":{"$ref":"#/components/schemas/TossApiError"},"resultType":{"description":"This is the processing result. `SUCCESS` Treat all values other than `FAIL` as failure. Generally,","enum":["FAIL","HTTP_TIMEOUT","NETWORK_ERROR","EXECUTION_FAIL","INTERRUPTED","INTERNAL_ERROR"],"type":"string"},"success":{"description":"It is always null on failure."}},"required":["error","resultType"],"type":"object"},"TossApiError":{"description":"This is detailed error information.","properties":{"data":{"description":"Additional error information. When the request limit is exceeded `retryAfterSeconds` is included.","type":"object"},"errorCode":{"description":"This is the error code. Refer to each API's business error code table.","type":"string"},"errorType":{"description":"This is an internal error classification value. For error categorization, `errorCode` use it.","format":"int32","type":"integer"},"reason":{"description":"This is a human-readable error description.","type":"string"},"title":{"description":"This is the error title. It is usually null.","type":"string"}},"required":["errorCode","reason"],"type":"object"},"TossApiValidationFail":{"description":"This is the response when request field validation fails.","properties":{"error":{"$ref":"#/components/schemas/TossApiValidationFailError"},"resultType":{"description":"This is the processing result. `SUCCESS` Treat all values other than `FAIL` as failure. Generally,","enum":["FAIL","HTTP_TIMEOUT","NETWORK_ERROR","EXECUTION_FAIL","INTERRUPTED","INTERNAL_ERROR"],"type":"string"},"success":{"description":"It is always null on failure."}},"required":["error","resultType"],"type":"object"},"TossApiValidationFailError":{"description":"This is detailed error information.","properties":{"data":{"description":"Additional error information. When the request limit is exceeded `retryAfterSeconds` is included.","properties":{"errorDetails":{"description":"This is a detailed list of field-level validation failures.","items":{"$ref":"#/components/schemas/TossApiFieldError"},"type":"array"}},"type":"object"},"errorCode":{"description":"This is the error code. Refer to each API's business error code table.","type":"string"},"errorType":{"description":"This is an internal error classification value. For error categorization, `errorCode` use it.","format":"int32","type":"integer"},"reason":{"description":"This is a human-readable error description.","type":"string"},"title":{"description":"This is the error title. It is usually null.","type":"string"}},"required":["errorCode","reason"],"type":"object"},"TossApiFieldError":{"description":"This is a detailed list of field-level validation failures.","properties":{"field":{"description":"This is the name of the field that failed validation.","type":"string"},"message":{"description":"This is the reason for the validation failure.","type":"string"},"rejectedValue":{"description":"This is a rejected input value."}},"type":"object"}}},"paths":{"/api-partner/v1/apps-in-toss/users/anon-key/verify":{"post":{"description":"It verifies whether the anonymous user identification key passed in the x-anon-key header is valid.\n\n### Business error code\n\nThe errors below return with HTTP 200 and `resultType: FAIL` response.\n\n| errorCode | Description                                     |\n| --------- | ----------------------------------------------- |\n| `4010`    | Authentication information could not be found.  |\n| `4095`    | Request limit exceeded. Please try again later. |\n\n**Request limit**: 3,000 times per minute per app","operationId":"verifyAnonKey","parameters":[{"description":"It's a key for authenticating users. In the Mini App SDK, [User.getAnonymousKey](https://developers-apps-in-toss.toss.im/documentation/sdk/domains-api/user/user.getanonymouskey) you can get it with the function","in":"header","name":"x-anon-key","required":true,"schema":{"type":"string"}}],"responses":{"200":{"content":{"application/json":{"schema":{"discriminator":{"mapping":{"FAIL":"#/components/schemas/TossApiFail","SUCCESS":"#/components/schemas/TossApiSuccessBoolean"},"propertyName":"resultType"},"oneOf":[{"$ref":"#/components/schemas/TossApiSuccessBoolean"},{"$ref":"#/components/schemas/TossApiFail"}]}}},"description":"The result of validating the anonymous user identification key comes back as true or false."},"400":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/TossApiValidationFail"}}},"description":"The request format is invalid. `error.data` is an empty object and `error.reason` is `Unknown Error` comes down. `x-anon-key` A missing header is returned as a business error in HTTP 200, not this response (`4010`)"},"500":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/TossApiFail"}}},"description":"This is an uncategorized server error. If it keeps failing, contact the partner support channel."}},"summary":"Validate anonymous user identification key","tags":["user-key"]}}}}
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://developers-apps-in-toss.toss.im/api/en/user-key.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
